New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 594944 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: incognito browser mode recoverable in normal browsing mode

Reported by markkoh...@gmail.com, Mar 15 2016

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs


VULNERABILITY DETAILS
Chrome browser in incognito recoverable in normal browser windows

VERSION
Chrome Version:  Version 50.0.2661.18 dev-m
Operating System: windows 10 64 bit Version 1511

REPRODUCTION CASE
I do not know how to do this but wish to report the bug as I discovered it and imagine it is easily replicated. I was browsing in normal tabs and incognito tabs simultaneously. The browser crashed for unknown reason. When I recovered the session, my incognito tabs opened in standard browser tabs and were no longer private, infact tracked and everything. 

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: browser, incognito tabs
Crash State: browser stopped responding, recovered upon relaunch
Client ID (if relevant): [see link above]

 
New Text Document.txt
1.1 KB View Download

Comment 1 by mea...@chromium.org, Mar 15 2016

Components: UI>Browser>Incognito Privacy
Labels: -Restrict-View-SecurityTeam
Thanks for the report. Can you reproduce the issue by triggering a crash? Without reproducible steps unfortunately there isn't much we can do here. There also doesn't seem to be an exploitable vulnerability here, so I'm dropping view restrictions and adding privacy labels.

Comment 2 by mea...@chromium.org, Mar 15 2016

Labels: -Type-Bug-Security Type-Bug
Labels: Needs-Feedback
@markkohner: Could you please respond to the comment #1

Appreciate your help.

Thank you.
hello,I will try and enable logging and reproduce the results or record a video of it. I will post if I find anything but I do not know what might have caused it so I am not sure how to reproduce.
Project Member

Comment 5 by sheriffbot@chromium.org, Mar 17 2016

Labels: -Needs-Feedback Needs-Review
Owner: rnimmagadda@chromium.org
Status: Assigned (was: Unconfirmed)
Thank you for providing more feedback. Assigning to requester "rnimmagadda@chromium.org" for another review.

For more details visit https://sites.google.com/a/chromium.org/dev/issue-tracking/autotriage - Your friendly Sheriffbot
I was not able to reproduce it with browsers crashing. When it originally
happened, I was forced to terminate the two browser windows at once
'stopped responding' was the message; and when I started Chrome the next
time I was prompted to recover the last session. The last session included
an incognito tab, but somehow it had saved this session and restored it as
a normal window. I am not technically inclined enough to interpret this
accurately but I think this does represent a possible security or at least
privacy issue. Unfortunately, it seems hard to reproduce. Infinite loops in
the browser windows seem to be independent and they do not cause the same
type of crash.
Cc: rnimmagadda@chromium.org
Labels: -Needs-Review Needs-Feedback
Owner: ----
Status: Unconfirmed (was: Assigned)
@markkohner: Could you please let us know if we can close this issue, since it is not crashing.

Thank you.
Cc: ranjitkan@chromium.org
Labels: -Needs-Feedback
Status: WontFix (was: Unconfirmed)
Closing the issue as did not hear back from user again. Please feel free to raise a new issue or reopen if it still persists or reappears.

Sign in to add a comment